All Apps and Add-ons

Splunk App for AWS: Why does creating a S3 input with nested folder structure not return any results?

ytenenbaum_splu
Splunk Employee
Splunk Employee

A Splunk customer using Splunk App for AWS and they have a problem with the S3 input. They did a few tests to check that the S3 Input is ingesting data and it was able to collect files from a single bucket (.txt files) without any issues. However, when they create an S3 Input and target it to a bucket that contains nested folder structure they're not getting any results, the logs in the buckets do not have any extension as such. They have tried this with ELB Access logs and Cloudtrail logs.

0 Karma
1 Solution

ytenenbaum_splu
Splunk Employee
Splunk Employee

They've solved it by adding a Bucket policy that allows the role to do an S3:GetObject on the Bucket. They overlooked this originally and this is what caused the issue. It appears to be working fine now and they're getting logs coming in nicely.

View solution in original post

ytenenbaum_splu
Splunk Employee
Splunk Employee

They've solved it by adding a Bucket policy that allows the role to do an S3:GetObject on the Bucket. They overlooked this originally and this is what caused the issue. It appears to be working fine now and they're getting logs coming in nicely.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...